DNS Tagging for Network Traffic Profiling and Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of the World Wide Web, driven by cloud-based services and content delivery networks, makes it difficult to understand and control the mapping between users, content owners, and hosts serving content, especially with the adoption of encryption and diverse optimization mechanisms, leading to a 'tangled' network environment that hinders effective security operations.
Innovation Solution
A passive traffic monitoring system that utilizes DNS queries and responses to correlate client IP addresses, server IP addresses, and fully qualified domain names (FQDNs) to map users, content owners, and hosts, providing insights into port-service mapping, automatic service label extraction, and flow-set generation, thereby simplifying network traffic profiling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud-based services and content delivery networks are used to meet scalability and availability requirements, then service delivery capability is improved, but network complexity and difficulty of understanding content mapping worsen
Solution Approach 1:
The patent introduces DNS tagging as an intermediary mechanism that embeds identification information into DNS queries and responses. This mediator connects clients to cloud services and CDNs while maintaining traceability of content ownership and service delivery paths, thus resolving the complexity issue without sacrificing service delivery capability
Solution Approach 2:
The system implements feedback loops by monitoring DNS traffic patterns, analyzing service delivery performance, and using this information to optimize content routing and CDN selection. This feedback mechanism enables dynamic adaptation to changing network conditions while maintaining clear visibility into content mapping relationships
2Reliability
If encryption (TLS/HTTPS) is adopted to protect end-users' privacy, then security is improved, but ability to perform security operations and monitor traffic worsens
Solution Approach 1:
The patent performs security analysis at the DNS layer before encrypted traffic is established. By examining DNS queries, response times, and tagging patterns prior to TLS connection establishment, the system can identify potential security threats, verify content legitimacy, and set up monitoring rules without requiring decryption of the actual traffic content
Solution Approach 2:
DNS acts as an intermediary that provides visibility into encrypted traffic flows. The patent uses DNS tagging to embed identification information that allows security operations to track and analyze encrypted traffic patterns, content delivery paths, and service associations without breaking encryption, thus maintaining both privacy protection and security monitoring capability
3Measurement precision
If manual approaches are used to address Web Content Cartography issues, then analysis accuracy is maintained, but productivity and scalability worsen
Solution Approach 1:
The patent implements automated DNS tagging and correlation systems that self-configure and self-analyze network traffic patterns. The system automatically extracts content ownership information, service delivery paths, and mapping relationships from DNS traffic without requiring manual intervention, thereby maintaining high analysis accuracy while achieving scalable automated operation
Solution Approach 2:
The patent creates a universal DNS tagging framework that can analyze multiple types of traffic patterns, content delivery mechanisms, and service architectures through a single automated system. This multi-functional approach maintains the precision of manual analysis methods while enabling simultaneous profiling of diverse network services and content flows at scale
Data Source
AI summary
A method for profiling network traffic of a network, including obtaining a plurality of flows comprising a plurality of client IP addresses, a plurality of server IP addresses, and a plurality of server ports, extracting a plurality of fully qualified domain names (FQDNs) from a plurality of DNS flows in the network traffic, analyzing correlation between the plurality of flows and the plurality of FQDNs to generate a result, and presenting the result to an administrator user of the network.


